Early-bird Discount
expires in
Register Now

Blog

Operationalization of the KC Identity Fabric and Reference Architecture with a Maturity Model

Blog Post

Operationalization of the KC Identity Fabric and Reference Architecture with a Maturity Model

Phillip Messerschmidt
Sep 03, 2025

Identity and Access Management (IAM) is far more complex than many people assume. While it is omnipresent in organizations, it is still frequently treated as a hidden infrastructure service which just needs to “work” in the background. As a result, IAM is often underestimated, underfunded, and under-strategized. Yet IAM is not simply infrastructure. It is a security service that can enable business growth, digital transformation, and secure collaboration across ecosystems. Without a clear plan, however, IAM quickly becomes an operational burden rather than a strategic advantage. 

Identity Fabric – from concept to practice 

Over the past years, the Identity Fabric has become a widely recognized foundation for modern IAM. It is no longer an abstract concept, but a strategic framework embraced by vendors, service providers, and enterprises alike. The core idea is straightforward but powerful: Provide seamless, controlled, and secure access for everyone and everything, from any location to any service. 

Figure 1: KuppingerCole Identity Fabric (Version 2025) 

The Identity Fabric illustrates how different identity types such as employees, customers, partners, devices, and services can interact with target systems. This access is enabled through functional capabilities. These capabilities are bundled into services, and these services are mapped to specific tool categories. In other words, the Identity Fabric turns the abstract question “how do we manage access for everyone to everything?” into a structured model. 

Figure 2: The KuppingerCole IAM Reference Architecture (Version 2025) 

The Reference Architecture as capability map 

The KuppingerCole Reference Architecture provides the necessary level of detail to bring the Identity Fabric to life. It is organized as a capability matrix along five functional layers and four domains which are the well-known “4 A’s.” By breaking IAM into clearly defined functional capabilities, the Reference Architecture helps organizations avoid the trap of viewing IAM only as products or tools. Instead, it establishes a structured view of what IAM must achieve and how these achievements fit into a business-aligned security ecosystem. 

This structured approach is not an academic exercise. It is the foundation for achieving a cohesive, adaptable, and future-proof IAM environment. Diving into the Reference Architecture is therefore essential, not only for strategy development but also for handling daily operational demands. 

Three ways of operationalization 

At EIC 2025, KuppingerCole presented the updated version of the Identity Fabric in a workshop and demonstrated three distinct approaches to operationalization: 

  • Flexible Reference Architectures 
    This part highlighted how the Reference Architecture can be used to flexibly change the scope of the Identity Fabric. One major takeaway was the presentation of the new draft version of the CIAM Reference Architecture, showing how customer-specific requirements can be mapped consistently into the same structured approach. 

  • Strategic Development 
    Here, KuppingerCole demonstrated how the frameworks can be used to assess an organization’s IAM landscape and derive a strategic roadmap in five steps: 
    • Maturity assessment, 
    • Definition of the target state, 
    • Gap analysis, 
    • Identification of action items,  
    • Roadmap creation. 

This structured sequence helps organizations move beyond buzzwords and develop a practical, measurable plan for improvement. 

  • Operational Development 
    Finally, the third chapter focused on daily IAM challenges and how do you resolve recurring operational issues with a structured, hands-on mentality. The Identity Fabric and Reference Architecture offer a common language to classify problems, highlight dependencies, and provide a structured pathway toward resolution. 

The feedback from this workshop was remarkably positive. Many attendees emphasized that this workshop had helped them greatly by showing them how to translate these frameworks into concrete steps for strategy and operations. 

The next step: Maturity as foundation 

While many organizations confidently state that they already have an IAM strategy, reality often tells a different story. Without a solid understanding of their own current state, these strategies remain vague and aspirational. At EIC 2025, the focus was on showing how to move forward in five steps. At the upcoming Identity Fabric Impact Day (IFID) on September 18, 2025, in Munich, the spotlight will shift to the very first step: The maturity assessment. 

A well-executed maturity assessment provides a structured overview of an organization’s functional capabilities. It helps build a common understanding across departments, prevents misunderstandings, and establishes a baseline for measuring progress. It also enables benchmarking against industry leaders transforming subjective assumptions into objective evaluations. 

Why maturity matters 

A maturity assessment is not simply about scoring an organization on a scale. It is about enabling clarity: 

  • Which IAM capabilities exist, and how well are they implemented? 
  • Where are the strengths, weaknesses andgaps? 
  • How do different levels of maturity interact and depend on each other? 
  • What is realistic to achieve as the next step? 

Without this clarity, organizations risk investing in the wrong initiatives or trying to adopt trends like Zero Trust or CIAM without having established the operational excellence to support them. The maturity assessment ensures that ambitions are matched with the current reality. 

What to expect in Munich 

At IFID, KuppingerCole will present a five-level maturity assessment model based on the Identity Fabric and the Reference Architecture. The event will provide concrete answers to key questions: 

  • How many maturity levels are really required? 
  • Which criteria are important to assess IAM capabilities? 
  • How exactly are the levels and criteria defined? 
  • How do the different levels relate to each other? 
  • Which possibilities exist to improve maturity step by step? 

In addition, participants will have the chance to meet directly with KuppingerCole experts, discuss their own challenges, and receive advice on applying these insights in their organizations. 

From frameworks to real progress 

The operationalization of the Identity Fabric and Reference Architecture is not a theoretical exercise. It is about providing clarity, structure, and practical guidance in a complex area that too often suffers from misunderstanding. Focusing on the maturity assessment is the next step and will help organizations establish a transparent foundation for strategic development and operational excellence. 

Join us in Munich on September 18, 2025, to see how KuppingerCole's frameworks can be transformed into actionable insights and how maturity can become the starting point for real progress in IAM. 


KuppingerCole Analysts AG
Roles & Responsibilities at KuppingerCole Analysts Dr. Phillip Messerschmidt joined KuppingerCole in January 2021 as Senior Advisor & Analyst. Today, as Lead Advisor, Phillip has responsibility for several customer projects and ensures the value of the projects for KuppingerCole customers. Background & Education After his studies in economics and finance, Phillip started working in a consulting firm and joined an ongoing IAM project of a large bank in Frankfurt. This laid a foundation for future projects and his career as a consultant. Phillip also incorporated the practical experience he gained into his dissertation "Profitability of Identity and Access Management in the Digital Transformation". Areas of coverage IAM (Identity & Access Management) Identity & Access Governance and Compliance (Least Privilege, SoD, Recertification, Risk-based Access Governance) Authorization (Authorization Models, RBAC, PBAC, ABAC, Implementation of Roles Models) IAM Processes (JML, Access Request, Approval Process, Role Maintenance, Recertification) Professional experience Prior to KuppingerCole, Phillip worked for various management consultancies, primarily advising major banks and financial service providers on challenges related to the IT security infrastructure on the topic of identity and access management (IAM). His focus was on functional content and activities, such as the establishment of a company-wide authorization structure, the cleansing of historical data and the functional design of IAM-relevant processes.
Almost Ready for IFID 2025?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.